Impact
Deserialization of untrusted data in the NextScripts social-networks-auto-poster-facebook-twitter-g plugin for WordPress allows an attacker to inject crafted PHP serialized objects. This object injection can lead to arbitrary code execution on the server, compromising confidentiality, integrity, and availability of the WordPress site. Based on the description, it is inferred that the attacker can supply malicious serialized data through the plugin’s input mechanisms to trigger the flaw.
Affected Systems
WordPress installations using the NextScripts social-networks-auto-poster-facebook-twitter-g plugin versions up to and including 4.4.7 are affected. The vulnerability applies to all sites that have not upgraded past version 4.4.7.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is reported as less than 1%, suggesting low current exploitation probability. The flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector involves an attacker sending malicious serialized data to the plugin’s processing endpoint, leading to object injection and potential remote code execution.
OpenCVE Enrichment